WGU E026 comprehesive exam with 100
questions and correct answers with
rationale graded A+
Part 1: Questions 1–25
1. What is the primary purpose of AI in IT automation?
A. To replace all IT staff permanently
B. To increase manual configuration work
C. To improve efficiency, consistency, and decision support in IT tasks
D. To eliminate the need for security controls
Correct Answer: C
Rationale: AI in IT automation is mainly used to streamline repetitive tasks, improve consistency, and
assist in decision-making. It supports IT professionals rather than eliminating all human involvement.
2. Which of the following is an example of supervised machine learning?
A. Grouping unknown network traffic by similarity
B. Training a model with labeled phishing and non-phishing emails
C. Randomly exploring a network to find devices
D. Compressing log files for storage
Correct Answer: B
Rationale: Supervised learning uses labeled data. A model trained on emails already labeled as
phishing or non-phishing is a classic example.
,3. Which machine learning type is most commonly used for anomaly detection in security logs when
labels are unavailable?
A. Supervised learning
B. Unsupervised learning
C. Reinforcement learning
D. Transfer learning
Correct Answer: B
Rationale: Unsupervised learning is useful when data is unlabeled and the goal is to find unusual
patterns or outliers, such as anomalies in log data.
4. In a security operations center (SOC), what is a common AI use case?
A. Physically installing cables
B. Detecting suspicious behavior in network traffic
C. Replacing power supplies in servers
D. Creating building access badges manually
Correct Answer: B
Rationale: AI is often used in SOC environments to detect threats, analyze traffic patterns, and
identify suspicious activities more efficiently.
5. Which Python library is widely used for data analysis in AI workflows?
A. Flask
B. Pandas
C. Paramiko
D. Ansible
Correct Answer: B
,Rationale: Pandas is commonly used for data manipulation and analysis, especially for preparing
datasets for machine learning.
6. What is a key benefit of automation in patch management?
A. It guarantees zero vulnerabilities
B. It reduces the need for testing
C. It helps deploy updates consistently and quickly
D. It removes the need for asset inventories
Correct Answer: C
Rationale: Automation improves the speed and consistency of patch deployment, though it does not
eliminate the need for testing or guarantee complete security.
7. Which of the following best describes a false positive in security detection?
A. A real attack that is missed
B. A benign event incorrectly flagged as malicious
C. A malicious event correctly identified
D. A system update that fails to install
Correct Answer: B
Rationale: A false positive occurs when normal or harmless behavior is incorrectly identified as a
threat.
8. Which metric is most useful when minimizing false negatives in malware detection is critical?
A. Precision
B. Recall
C. Throughput
D. Latency only
Correct Answer: B
, Rationale: Recall measures how many actual positive cases are correctly identified. When false
negatives are dangerous, recall is especially important.
9. What is the main function of a playbook in security orchestration, automation, and response
(SOAR)?
A. To physically secure data center doors
B. To define automated response steps for security events
C. To build machine learning hardware
D. To replace all SIEM functionality
Correct Answer: B
Rationale: A SOAR playbook outlines automated and semi-automated actions taken in response to
specific events or alerts.
10. What does SIEM stand for?
A. Secure Internet Encryption Model
B. Security Information and Event Management
C. System Integrity Evaluation Module
D. Standardized Incident Escalation Mechanism
Correct Answer: B
Rationale: SIEM stands for Security Information and Event Management, a system used to collect,
correlate, and analyze security logs and events.
11. Which automation tool is agentless and commonly uses YAML playbooks?
A. Docker
B. Ansible
C. Wireshark
D. Splunk
questions and correct answers with
rationale graded A+
Part 1: Questions 1–25
1. What is the primary purpose of AI in IT automation?
A. To replace all IT staff permanently
B. To increase manual configuration work
C. To improve efficiency, consistency, and decision support in IT tasks
D. To eliminate the need for security controls
Correct Answer: C
Rationale: AI in IT automation is mainly used to streamline repetitive tasks, improve consistency, and
assist in decision-making. It supports IT professionals rather than eliminating all human involvement.
2. Which of the following is an example of supervised machine learning?
A. Grouping unknown network traffic by similarity
B. Training a model with labeled phishing and non-phishing emails
C. Randomly exploring a network to find devices
D. Compressing log files for storage
Correct Answer: B
Rationale: Supervised learning uses labeled data. A model trained on emails already labeled as
phishing or non-phishing is a classic example.
,3. Which machine learning type is most commonly used for anomaly detection in security logs when
labels are unavailable?
A. Supervised learning
B. Unsupervised learning
C. Reinforcement learning
D. Transfer learning
Correct Answer: B
Rationale: Unsupervised learning is useful when data is unlabeled and the goal is to find unusual
patterns or outliers, such as anomalies in log data.
4. In a security operations center (SOC), what is a common AI use case?
A. Physically installing cables
B. Detecting suspicious behavior in network traffic
C. Replacing power supplies in servers
D. Creating building access badges manually
Correct Answer: B
Rationale: AI is often used in SOC environments to detect threats, analyze traffic patterns, and
identify suspicious activities more efficiently.
5. Which Python library is widely used for data analysis in AI workflows?
A. Flask
B. Pandas
C. Paramiko
D. Ansible
Correct Answer: B
,Rationale: Pandas is commonly used for data manipulation and analysis, especially for preparing
datasets for machine learning.
6. What is a key benefit of automation in patch management?
A. It guarantees zero vulnerabilities
B. It reduces the need for testing
C. It helps deploy updates consistently and quickly
D. It removes the need for asset inventories
Correct Answer: C
Rationale: Automation improves the speed and consistency of patch deployment, though it does not
eliminate the need for testing or guarantee complete security.
7. Which of the following best describes a false positive in security detection?
A. A real attack that is missed
B. A benign event incorrectly flagged as malicious
C. A malicious event correctly identified
D. A system update that fails to install
Correct Answer: B
Rationale: A false positive occurs when normal or harmless behavior is incorrectly identified as a
threat.
8. Which metric is most useful when minimizing false negatives in malware detection is critical?
A. Precision
B. Recall
C. Throughput
D. Latency only
Correct Answer: B
, Rationale: Recall measures how many actual positive cases are correctly identified. When false
negatives are dangerous, recall is especially important.
9. What is the main function of a playbook in security orchestration, automation, and response
(SOAR)?
A. To physically secure data center doors
B. To define automated response steps for security events
C. To build machine learning hardware
D. To replace all SIEM functionality
Correct Answer: B
Rationale: A SOAR playbook outlines automated and semi-automated actions taken in response to
specific events or alerts.
10. What does SIEM stand for?
A. Secure Internet Encryption Model
B. Security Information and Event Management
C. System Integrity Evaluation Module
D. Standardized Incident Escalation Mechanism
Correct Answer: B
Rationale: SIEM stands for Security Information and Event Management, a system used to collect,
correlate, and analyze security logs and events.
11. Which automation tool is agentless and commonly uses YAML playbooks?
A. Docker
B. Ansible
C. Wireshark
D. Splunk